Skip to content
arrow_back
ISM-2093policyASD Information Security Manual (ISM)

Role-Based Access Controls in AI Applications

Access to sensitive data in AI apps is restricted based on user roles.

record_voice_over

Plain language

This control ensures that people can only access sensitive information in AI applications if they have a role that needs it. Without these restrictions, sensitive data could fall into the wrong hands, leading to privacy breaches and potential business losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Role-based access controls are implemented for AI applications to restrict access to sensitive data.
policyASD Information Security Manual (ISM)ISM-2093
priority_high

Why it matters

If role-based access controls aren't used, sensitive data could be accessed by unauthorised users, potentially leading to data breaches and financial loss.

settings

Operational notes

Regularly review and update user roles to accommodate job changes or personnel shifts, ensuring access to sensitive data remains appropriate.

build

Implementation tips

  • Managers should assign roles carefully: Identify the employees who need access to sensitive data within AI applications based on their job responsibilities. Document their roles and ensure they are updated as responsibilities change.
  • IT teams should set up user accounts: Configure the software to link each user account to their assigned role, which dictates the level of access to data they have. Use software tools that allow for easy role-based access settings.
  • HR should train employees on access policies: Provide clear guidelines to staff about data access and privacy rules relevant to their roles. Conduct regular training to reinforce these policies and ensure understanding.
  • System owners should review access permissions periodically: Schedule regular checks (at least quarterly) to ensure that who has access to sensitive data aligns with current job roles and tasks. Adjust roles as job functions evolve.
  • Security teams should audit access logs: Use software to track and monitor who accesses what information and when, allowing for quick detection of any unauthorised access attempts.
fact_check

Audit / evidence tips

  • Askthe role-based access control policy document: Check this document to see if it outlines how roles are assigned and access is managed. Good if it details roles, responsibilities, and the process for changing access
  • Goodoutcome shows correct alignment with minimal discrepancies
  • Askto see recent access log reports: Review these logs for entries showing anomalous access attempts or misuses of access rights. Good results show consistent, authorised access patterns with no irregular activity
  • Request documentation of recent role reviews: Check for records of when access roles were last reviewed and updated. Good if there is documented evidence of regular reviews with clear notes on changes made.
  • Asktraining records on access policy: Review employee training completion records to confirm that staff received instructions on access policies. Good if all relevant staff have completed up-to-date training
link

Cross-framework mappings

How ISM-2093 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 5.15ISM-2093 requires organisations to implement RBAC in AI applications to prevent unauthorised access to sensitive AI data
Annex A 8.3ISM-2093 requires RBAC for AI applications to restrict access to sensitive AI data
sync_altPartially overlaps(1)expand_less
Annex A 5.18ISM-2093 requires RBAC enforcement in AI applications so only authorised roles can access sensitive AI data
handshakeSupports(1)expand_less
Annex A 5.3Annex A 5.3 requires organisations to segregate conflicting responsibilities to reduce opportunities for misuse, fraud or error

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-RA-ML3.1ISM-2093 requires role-based access controls (RBAC) for AI applications to restrict access to sensitive AI data to authorised personnel

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls